CVE-2016-10942: SQL Injection
Published Sep 13, 2019
·Updated
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insertid parameter exploitable via CSRF.
Affected Software
1 affected component
podlove Podlove Podcast Publisher WordPress<2.3.16
Event History
Sep 13, 2019
CVE Published
via MITRE·11:53 AM
Data Sourced
via MITRE·11:53 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10942?
CVE-2016-10942 is considered a critical vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2016-10942?
To fix CVE-2016-10942, update the Podlove Podcast Publisher plugin to version 2.3.16 or higher.
3
What systems are affected by CVE-2016-10942?
CVE-2016-10942 affects the Podlove Podcast Publisher plugin for WordPress versions prior to 2.3.16.
4
Can CVE-2016-10942 be exploited remotely?
Yes, CVE-2016-10942 can be exploited remotely through a cross-site request forgery (CSRF) attack.
5
What are the potential impacts of CVE-2016-10942?
The impacts of CVE-2016-10942 include unauthorized access to database information and potential manipulation of data.